Microsoft has rolled out a batch of 22 critical security updates to address severe vulnerabilities in its products, including one that’s already being exploited by attackers. The tech giant has patched the issue internally, but hasn’t disclosed any information about the attacks involving this flaw.
The most pressing concern is a zero-day vulnerability tracked as CVE-2026-69836, which affects Microsoft Entra ID. This critical flaw could be exploited for remote code execution (RCE), allowing attackers to gain unauthorized access to systems and potentially cause significant damage. Fortunately, Microsoft has taken proactive measures to address the issue on its servers, so no action is required from customers.
However, other patches are addressing critical and high-severity flaws in various Microsoft products, including Azure, Entra ID, Exchange, Fabric, and Partner Center. The most severe issues include elevation-of-privilege (EoP) bugs in Azure SQL Database, Azure Arc, and Exchange Online, all of which have a CVSS score of 10/10. This means that attackers could potentially gain elevated privileges to perform actions they shouldn’t be able to do.
In addition to the Entra ID vulnerability, several other critical EoP issues were resolved, including flaws in Azure SQL Database, Microsoft Fabric, and Azure Data Factory. High-severity vulnerabilities were also patched in Azure Virtual Machines, Partner Center, and various other products.
Notably, earlier this week, Microsoft fixed a high-severity command injection bug in Copilot that could be exploited remotely for information disclosure (CVE-2026-24301). This vulnerability is significant because it allows attackers to inject malicious commands into the system, potentially leading to unauthorized access or data theft.
Microsoft is also working on patches for ShieldBreak, a zero-day Defender exploit dropped by security researcher Nightmare Eclipse last week. The company assesses that the vulnerability targeted by ShieldBreak is a high-severity bug (CVE-2026-69414), but has not shared any information about attacks involving this flaw.
The fact that Microsoft has been proactive in addressing these vulnerabilities and has taken steps to mitigate them on its servers is a positive development for customers. However, it’s essential for organizations to stay vigilant and ensure their systems are up-to-date with the latest patches. This includes regularly checking for updates, configuring systems to automatically apply patches, and monitoring for suspicious activity.
While no customer action is required in most cases, it’s crucial to remember that even seemingly minor issues can have significant consequences if left unaddressed. By prioritizing security and staying informed about vulnerabilities and patches, organizations can reduce their risk of being compromised by attackers.
Source: SecurityWeek — 2026-08-21